Skip to content

Update Bouncy Castle #2125

New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Closed
msymons opened this issue May 22, 2023 · 1 comment
Closed

Update Bouncy Castle #2125

msymons opened this issue May 22, 2023 · 1 comment

Comments

@msymons
Copy link

msymons commented May 22, 2023

docker-java 3.3.0 has a transitive dependency on bcprov-jdk15on 1.66 via bcpkix-jdk15on 1.66.

The former has a vulnerability CVE-2020-15522

Whilst this vulnerability may (or may not) impact docker-java, it will still be picked up by SCA tools and reported as being a potential problem.

There is a fix available and thus an upgrade of ${bouncycastle.version} should sort things out.

  • An upgrade to 1.67 will address the vulnerability, as well as CVE-2020-28052 (affects 1.65 and 1.67)
  • An upgrade to 1.70 will use the last version released of bcpkix-jdk15on
  • The latest version of bouncy castle is 1.73 (and addresses a security advisory that does not have a CVE). This would nessitate updating the component artifactId to bcpkix-jdk18on. See Latest Java Releases
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

2 participants